Home Malware Programs Trojans Generic18.EXG

Generic18.EXG

Posted: August 10, 2011

Generic18.EXG is predominantly used as an alias for the rogue anti-virus program Antivirus 7, although, in rare cases, it may also refer to unrelated Trojans. Due to the variable nature of Generic18.EXG as a PC threat, you should look for the relevant symptoms, such as the presence of unfamiliar AV software or unusual system changes, to determine what kind of danger Generic18.EXG poses to your computer. In most situations, SpywareRemove.com malware researchers have found that Generic18.EXG, as a component of Antivirus 7, is dangerous primarily for its ability to create fake infection information, while stealing your credit card information. However, Trojan versions of Generic18.EXG may be capable of other hostile acts, such as disabling your security software or installing other harmful programs.

A Dissection of the Dangers of a Fake Anti-Virus Generic18.EXG

In its Antivirus 7 form, Generic18.EXG presents standard rogue security software problems. Attacks that are related to Generic18.EXG as a component of Antivirus 7 are as follows:

  • Generic18.EXG may attempt to hijack your browser to control which websites you visit. Although Generic18.EXG may change your homepage to the Antivirus 7 homepage or otherwise redirect you to such fraudulent websites, the primary purpose of these hijacks is to block your access to anti-malware sites that could help you delete Generic18.EXG.
  • Generic18.EXG will almost certainly create various types of fake information that pretend that your PC is more-heavily infected than it really is, especially in the form of fake system scans and infection alerts. Two samples of these fake warnings that SpywareRemove.com malware analysts have found are shown below:

    Security Alert
    Virus Alert!
    Application can't be started! The file [random file] is damaged. Do you want to activate your anti-virus software now?

    Windows Security Alert
    Windows reports that computer is infected. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the scan your computer. Your system might be at risk now.

  • To go along with its fake infection alerts, Generic18.EXG may also block many different security and utility programs, by pretending that they're infected. Disabling Generic18.EXG and other Antivirus 7 components with Safe Mode or a different type of safe boot method will allow you to regain the usage of any programs that Generic18.EXG has blocked.

Since Generic18.EXG's Antivirus 7 is part of an overwhelmingly huge family of rogue anti-virus programs, Generic18.EXG infections may also occur with clones of Antivirus 7, including (but not restricted to) AntiMalware GO, Antivir, Antivirus Protection Trial, AntiVira AV, Antivirus .NET and Antivirus Monitor.

The Trojan Generic18.EXG That Doesn't Even Pretend to Be Your Friend

Along with its rogue anti-virus aspirations, Generic18.EXG may also be indicative of an unrelated Trojan infection, including Trojan.Generic.4153940 and Win32/Kryptik.EUW. Although these labels are generic and may not identify all of the traits that a Trojan Generic18.EXG can possess, SpywareRemove.com malware experts have found the following attacks to be most likely with Generic18.EXG Trojans:

  • Generic18.EXG may function in the form of a dropper Trojan by installing other harmful programs, potentially including Vundo Trojans, scamware in the style of System Cleaner or other rogue security products, and spyware like IMMonitor that steal confidential information.
  • In addition to the above, Generic18.EXG may also use backdoor Trojan attacks that hamper your computer's security. Common backdoor Trojan invasions include changing firewall or port settings, blocking security software and hijacking web browsers to redirect them away from helpful websites.

You can expect Generic18.EXG Trojans to launch themselves without permission, and you should use proper anti-malware applications to find and delete Generic18.EXG components rather than trying to identify all parts of a Generic18.EXG infection by yourself.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ProgramData%\Microsoft\Windows\Start Menu\AV7.0 File name: %ProgramData%\Microsoft\Windows\Start Menu\AV7.0
Mime Type: unknown/0
%AllUsersProfile%\Microsoft\Windows\Start Menu\AV7.0 File name: %AllUsersProfile%\Microsoft\Windows\Start Menu\AV7.0
Mime Type: unknown/0
%ProgramFiles%\AV7.0 File name: %ProgramFiles%\AV7.0
Mime Type: unknown/0
antivirus7.exe File name: antivirus7.exe
File type: Executable File
Mime Type: unknown/exe
bin_2004_b7.exe File name: bin_2004_b7.exe
File type: Executable File
Mime Type: unknown/exe
UpdateExplorer.dll File name: UpdateExplorer.dll
File type: Dynamic link library
Mime Type: unknown/dll

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{458289BD-886E-4115-A8D7-F1E8D8DC2EC1}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\{RunKeys}AV7.0
Loading...